Total CVEs

150,976

Critical Severity

5,036

High Severity

17,677

Last 7 Days

2,131
Quick preset (or use dates below)
Clear Filters
Showing 2,541 - 2,560 of 150,976 CVEs

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used...

Vendor: PowerDNS
Product: Recursor
Published: Jul 23, 2026
Source: NVD
CVE-2026-16723 CRITICAL - 9.0

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Vendor: Alibaba
Product: Fastjson
Published: Jul 23, 2026
Source: NVD
CVE-2026-16287 HIGH - 7.8

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

Vendor: TUBITAK BILGEM Software Technologies Research Institute
Product: pardus-update
Published: Jul 23, 2026
Source: NVD
CVE-2024-58330 HIGH - 7.5

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Vendor: Bosch
Product: Camera Firmware
Published: Jul 23, 2026
Source: NVD
CVE-2024-58023 HIGH - 8.4

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

Vendor: Bosch
Product: Bosch Configuration Manager
Published: Jul 23, 2026
Source: NVD
CVE-2026-9729 MEDIUM - 6.4

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the save...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9713 HIGH - 7.5

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping o...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9635 MEDIUM - 6.4

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which ...

Published: Jul 23, 2026
Source: NVD

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.

Vendor: Linux-Gaming
Product: PortProtonQt
Published: Jul 23, 2026
Source: NVD

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.

Vendor: SELinuxProject
Product: selinux
Published: Jul 23, 2026
Source: NVD
CVE-2026-12421 HIGH - 7.2

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Product: ARforms
Published: Jul 23, 2026
Source: NVD
CVE-2026-9577 MEDIUM - 4.8

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator'...

Published: Jul 23, 2026
Source: NVD
CVE-2026-9066 MEDIUM - 6.1

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress pl...

Published: Jul 23, 2026
Source: NVD

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

Vendor: SELinuxProject
Product: selinux
Published: Jul 23, 2026
Source: NVD
CVE-2026-14291 HIGH - 7.5

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced...

Vendor: Unknown
Product: security-ninja-premium
Published: Jul 23, 2026
Source: NVD
CVE-2026-12082 HIGH - 7.5

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

Vendor: Unknown
Product: Praison AI SEO
Published: Jul 23, 2026
Source: NVD
CVE-2026-7534 HIGH - 7.2

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionall...

Published: Jul 23, 2026
Source: NVD
CVE-2026-7232 HIGH - 7.2

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

Published: Jul 23, 2026
Source: NVD
CVE-2026-64600 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab ...

Vendor: Linux
Product: Linux
Published: Jul 23, 2026
Source: NVD